Web Application Penetration Testing
Comprehensive security assessment of web applications following OWASP methodology, specialising in XSS, SQL injection, SSRF, RCE, LFI and CSRF.
// Offensive Security Researcher · Penetration Tester · Application & API Security Engineer
Three-plus years of hands-on web and API penetration testing: 2000+ vulnerabilities reported across 150+ organisations, a publicly disclosed U.S. Department of Defense SQL injection, and a top-50 global rank on the HackerOne VDP leaderboard.
I'm an offensive security researcher and penetration tester based in Dhaka, Bangladesh, currently working as a Security Engineer at Disclosify, where I run manual web application and API penetration tests for client organisations against OWASP and PTES methodology. Alongside client work, I've spent the last three-plus years hunting vulnerabilities independently on HackerOne and Bugcrowd — from business-logic flaws to blind SQL injection — and mentoring newer researchers through Daffodil International University's Cyber Security Club.
Across both tracks I've filed 2000+ vulnerability reports across 150+ organisations, sustaining an 85–90% acceptance rate on my client work at Disclosify. My published findings include a publicly disclosed unauthenticated SQL injection on a U.S. Department of Defense system and a CVSS 9.8 business-logic flaw. I hold certifications spanning web, API and network security — eWPTX v3, CASA, ASCP, CNSP and CAP — and I'm actively looking for a fully remote role, or one offering visa sponsorship and relocation, with a security-focused team in Europe or the US.
Engagement types available for client assessments and freelance work, alongside full-time roles.
Comprehensive security assessment of web applications following OWASP methodology, specialising in XSS, SQL injection, SSRF, RCE, LFI and CSRF.
Security testing for iOS mobile applications, including binary analysis, API testing, and a review of on-device data storage.
External and internal network security assessments to identify misconfigurations, weak protocols and exploitable services.
Full red team engagements covering exploitation, privilege escalation, pivoting, persistence and defense-evasion techniques.
A selection of vulnerabilities I've responsibly disclosed — each verified end-to-end with a working proof of concept before submission.
Identified a time-based blind SQL injection in the URI path of a U.S. Government PKI endpoint with no authentication required, resulting in full database disclosure. Publicly disclosed on HackerOne.
View public reportDiscovered a business-logic vulnerability in an unvalidated API endpoint that allowed unauthorized account balance top-up — rated CVSS 9.8 by the program.
Read the write-upFound and safely verified a P1 time-based blind SQL injection in an undocumented GraphQL endpoint, enumerating dozens of backend tables on a PostgreSQL/Greenplum database.
Read the write-upResponsibly disclosed a reflected cross-site scripting vulnerability directly to Oracle's security team, then built and published a Nuclei detection template for the wider community.
Additional confirmed findings — XSS, CSRF, SSRF, path traversal, IDOR and configuration disclosure — earned acknowledgement from Sony, BMW, American Airlines, ServiceNow and Hotmart. See Achievements.
Client-facing security engineering, independent research, and community leadership.
Disclosify · disclosify.io · Dhaka, Bangladesh
HackerOne & Bugcrowd · Remote
CodeAlpha · Remote
DIU Cyber Security Club · Dhaka, Bangladesh
DIU Cyber Security Club · Dhaka, Bangladesh
DIU Cyber Security Club · Dhaka, Bangladesh
DIU Computer Programming Club · Dhaka, Bangladesh
Methodology on the left, tooling on the right — the full stack I bring to an engagement.
Academic background, industry certifications, and standards training.
Daffodil International University, Dhaka, Bangladesh
Nizam Uddin Azgar Ali Degree College, Bangladesh
Leaderboard standing, vendor acknowledgements and competitive results.
Recognised by security teams at:
Training: TryHackMe Junior Penetration Tester path · PortSwigger Web Security Academy labs · ICONCS 2022 CTF volunteer.
Tooling I've built to scale my own research — and one platform I've shipped for others to use.
A self-serve SaaS platform for security teams and bug bounty hunters, unifying active scanning, deep reconnaissance and automated triage into one workflow. Scope Guard validates every target before a scan runs, and proof-of-concept verification keeps findings signal over noise.
Visit MultiScanPublic Nuclei templates for real-world findings, including detection logic for the Oracle ORDS/APEX 24.2 reflected XSS I disclosed to Oracle's security team.
Self-hosted pipeline that runs subdomain enumeration and vulnerability scanning in parallel across large target lists, driving a headless browser for JS-heavy targets and feeding results straight into my triage workflow.
Automated XSS detection and exploitation toolkit for identifying cross-site scripting vulnerabilities across bug bounty targets.
Custom Burp Suite extension for automated parameter discovery and SQL injection testing, built to speed up repetitive manual-testing steps.
Write-ups from the field, and sessions delivered to the community.
The methodology behind the CVSS 9.8 business-logic finding, from spotting the unvalidated endpoint to safely proving impact.
Read on MediumDiscovering and safely verifying a P1 blind SQL injection hiding behind an undocumented GraphQL schema.
Read on MediumA four-hour, in-person technical session on API security, IDOR and access-control failures.
Event pageLive, hands-on bug-hunting walkthrough for club members.
Event pageGuest talk on breaking into bug bounty hunting.
Event pageAvailable for remote-first security engineering roles, consulting engagements and coordinated disclosure. I usually reply within a day.